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Abstract 

We introduce a notion of Kripke model for classical logic for which we constructively 
prove soundness and cut-free completeness. We discuss the novelty of the notion and 
its potential applications. 
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1. Introduction 

Kripke models have been introduced as means of giving semantics to modal logics 



and were later used to give semantics for intuitionistic logic as well, cf . 11221 12311 . 
The purpose of the present paper is to show that Kripke models can also be used as 
semantics for classical logic. Of course, Kripke semantics can be indirectly assigned 
to classical logic by means of some appropriate double-negation translation, as in fstl, 
but our goal here is to provide a direct presentation of a notion of Kripke semantics for 
classical logic. 

We will use the LK^p sequent calculus of |Ql to represent proofs, but the conclu- 
sions given apply to any complete formal system for classical logic. There are at least 
two reasons for choosing LK^^: first, it is a typing system for a calculus very close to 
/l-calculus and we are ultimately interested in the computational content of classical 
logic; second, the symmetry of left/right distinguished formulae of LK^^ allows to give 
two dual notions of models, of which only one needs to be, and is, presented in this 
paper, while the other can be derived by analogy. 

This paper is organised as follows. Section 2 introduces the notion of classical 
Kripke model, based on two modifications to the traditional notion, and discusses the 
relationship between the traditional and our notion. Section 3 introduces the sequent 
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calculus LK^^ and gives a soundness theorem for it. Section 4 proves a completeness 
theorem for a universal model constructed from the deduction system itself. Section 5 
is the concluding section which discusses related and future work. 

We use the standard inductive definition of predicate logic formulae for the connec- 
tives {T, ±, A, V, — >, 3, V). The language has infinitely many constants. A sentence is a 
formula where all variables are bound by quantifiers. An atomic formula is one which 
is not built up from logical connectives, i.e. it is one built up of a predicate symbol. 
The shorthand -lA stands for A — » ±. 

All statements and proofs are constructive. 



2. Classical Kripke Models 

Kripke models can be considered as the "most classical" of all the semantics for 
intuitionistic logic, for two reasons: first, each of the 'possible worlds' that define a 
Kripke model is a classical world in itself (where either an atom or its negation are 
true); second, it is the single of the semantics for intuitionistic logic which has only 
a classical proof of completeness, when disjunction and existential quantification are 
considered^ 

In the last two decades, the Curry-Howard correspondence between intuitionistic 
proof systems and typed lambda-calculi has been extended to classical proof systems 
LI 7, 29, 8]. The idea for introducing direct-style Kripke models for classical logic came 
from their usefulness in providing normalisation-by-evaluation for intuitionistic proof 
systems To account for a classical proof system we modify the traditional notion 

of Kripke model in the following two ways. 

Not taking the forcing relation as primitive. We take as primitive the notion of "strong 
refutation", and define forcing in terms of it@ The forcing definition we get in this 
way partly coincides with the traditional definition of forcing, as explained in subsec- 
tion O 



Allowing certain nodes to validate absurdity. We allow certain possible worlds to be 
marked as "fallible", or "exploding". This approach has been taken for fCripke models 



in 1351], for Beth models by Friedman 113 lH and is necessary in order to have a con- 
structive proof of completeness, in the view of the meta-mathematical results from 
i2l, ,26.,27i1 . which preclude constructive proof^ of completeness in case one wants to 
retain that absurdity must never be valid in a possible worlcfl 

Definition 1. A classical Kripke model is given by a quintuple (K, <, D, iij, it-j^), K in- 
habited, such that 



' There is an intuitionistic proof in (33l . but it makes use of the fan theorem which is not universally 
recognised as constructive. 

^For an alternative, see the discussion on dual models in Section 5. 

' Strictly speaking, the cited results show that having a constructive proof of completeness implies having 
a proof of Markov's Principle, 

Extending the class of Boolean models with inconsistent models is also the key to the constructive proof 
of the classical completeness theorem in (24ll , For an analysis of that result, see 01 , 
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• {K, <) is a poset of "possible worlds"; 

• D is the " domain function" assigning sets to the elements of K such that 

Vw, w' eK,(w <w' ^ D{w) c D(w')) 

i.e., D is monotone; 

Let the language be extended with constant symbols for each element of T) :— 
U{D(w) : w 6 /:). 

• (— ) : (— ) llj is a binary relation of "strong refutation " between worlds and atomic 
sentences in the extended language such that 

- w : X{di, ...,d„) lis d, e D(w) for each i e {I, ...,n}, 

- (Monotonicity) w : X{di, ...,dn) iij & w < w' => w' : X{d\, ...,d„) ilj, 

• (— ) Ihj^ is a unary relation on worlds labelling a world as "exploding ", which is 
also monotone: 

W &.W <w' ^ w' lhj_ . 

The strong refutation relation is extended from atomic to composite sentences in- 
ductively and by mutually defining the relations of forcing and (non-strong) refutation. 

Definition 2. The relation (-) : (-) iij of strong refutation is extended to the relation 
between worlds w and composite sentences A in the extended language with constants 
in Diw), inductively, together with the two new relations: 

• A sentence A is forced in the world w (notation w :h A) if any world w' > w, 
which strongly refutes A, is exploding; 

• A sentence A is refuted in the world w (notation w : A Ihj if any world w' > w, 
which forces A, is exploding; 

• w : A A B Us ifw : A h or w : B ih; 

• w : Av B Hj ifw : A Ih and w : B Ih; 

• w : A ^ B iij ifw :ih A and w : B ih; 

• w : Vjc.A(jc) iIj ifw : A{d) n- for some d e D{w); 

• w : 3x.A(x) iij if, for any w' > w and d e D{w'), w' : A{d) ih; 

• ± is always strongly refuted; 

• T is never strongly refuted. 
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The notions of forcing and refutation can be somewhat understood as the classical 
notions of being true and being false. However, a statement of form P => w ih^ should 
not be thought of as negation of P at the meta-level, because in the concrete model we 
provide in section H) w is always an inhabited set. In other words, we never use ex 
falso quodlibet at the meta-level to handle exploding nodes. 

The notion of strong refutation is more informative than the notion of (non-strong) 
refutation, not only because the former implies the latter, but also because, for example, 
having w : A /\ B tells us which one of A, B is refuted, while w : A A B \\- does not. 

A more detailed characterisation of the notions is given in the rest of this section. 

Lemma 3. Strong refutation, forcing and refutation are monotone in any classical 
Kripke model. 

Proof. The monotonicity of strong refutation can be proved by induction on the for- 
mula in question, while that of forcing and refutation is obviously true. □ 

Lemma 4. Strong refutation implies refutation: In any world w and for any sentence 
A, w : A Us implies w : A ih. 

Proof. Suppose w : A h,, w' > w and w' A. Then w' is exploding because w' : A II5 
by monotonicity. Since w' was arbitrary, w : A \\-. □ 

2.1. Relation to Traditional Forcing and Further Properties 

It is natural to ask what is the relationship between traditional intuitionistic forcinglsi] 
and our forcing whose definition relies on a more primitive notion. Lemmas |5] and [8] 
give that the two notions (superficially) coincide on the fragment of formulae con- 
structed by A,V, T) 

Lemma 5. The following statements hold. 

w -.h A ^ B <=> for allw' >w,w' -.h A ^ w' -.W- B (1) 

w:\\-AaB <=> w -.h A and w -.W- B (2) 

w Vx.A(x) <=^ for all w >w and d e D(w'), w' :il- A(d) (3) 

w A V B <= w :ih A or w :\\- B (4) 

w ~^x.A{x) <= for some d e D{w), w :ih A(ii) (5) 

Proof. LemmaOand Lemma|4]are used implicitly in the following proof. 

([T]l Left-to-right: Suppose w' > w and w' wv A. To show w' :\v B we let w" > w' 
and w" : B itj and have to show that w" is exploding. Since then w" : A — > B 1I5 
holds by monotonicity and Lemma |4] the claim follows from the definition of 
w ;iH A — > B. 

Right-to-left: Suppose w' > w and w' : A ^ B itj, i.e., w' A and w' : B ih. 
We have to show w' is exploding. But, this is immediate, since w' B by 
assumption. 
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(|2|l Left-to-right: Suppose w' > w and w' : A h,. Then w' : A ih, and so w' : A A Z? llj. 
This implies that w' is exploding, that is, w :if- A. Similarly, we can show w :\\- B. 

Right-to-left: Suppose w' > w and w' : A A B n^. Therefore we have w' : A ¥ or 
w' : B lb. Each case leads to w' since w' :ii- A and w' :ii- B by monotonicity. 

(O Left-to-right: Suppose w" > w' > w, d e D(w'), and w" : A{d) itj. Then 
w" : "ix.Aix) lij, so w" is exploding. 

Right-to-left: Suppose w' > w and w' : Vx.A(x) lij, i.e., w' : A((i) if- for some 
d E So w' is exploding by assumption. 

The rest of the cases are obvious. □ 

Note, however, that although the definitions of our and intuitionistic forcing "match" 
on the fragment {— », A, V, T), that does not mean that a formula in that fragment is 
forced in our sense if and only if it is forced in the intuitionistic sense. The law of 
Peirce ((A — » B) — > A) — > A is one counterexample to that, it is classically but not in- 
tuitionistically forced; this is so because in our forcing, hidden under the surface, there 
is a notion of refutation which can be used. 

Remark 6. The following do not hold in general, even if reasoning classically. 

• w :li- A V Z? w :ih Aorw :ii- B. 

• w :¥ 3x.A(x) => for some t € D{w), w :ih A(t). 
The explanation is deferred to Remark \20\ 

Leiiuna 7. Given a classical Kripke model TC, the following hold. 

1. w : A ^ B n- ijfw : A ^ B iij. 

2. w : Ay Bh ijf w : Ay B 

3. w : 3x.A{x) ih ijf w: 3x.A{x) ilj. 

4. Ifw : A\\- orw : B w-, then w : A A B ih. 

5. Ifw : A(d) h for some d E D{w), then w : Vx.Aix) ih. 

Proof. 1 . Right-to-left is LemmalU 

Left-to-right: Suppose w' > w and w' : A h,. In order to show that w' is exploding 
it suffices to show w' :if- A — » B. For this assume w" > w' and w" : A ^ B ih,, 
i.e., w" :\\- A and w" : B ih. Then w" is exploding since we have w" : A iij by 
monotonicity. Similarly, we can show w : B W. 

2. Right-to-left is Lemma|4] 

Left-to-right: Suppose w' > w and w' :\\- A. Then by Lemma|5j w' :ii- A V B holds. 
So w' is exploding. That is w : A if-. Similarly, w : B ih holds. 

3. Right-to-left is Lemma|4] 

Left-to-right: Suppose w" > w' > w, d ^ D(w') and w" :\\- A(d). Then by 
Lemma|5j w" :if- 3x.A(x). So w" is exploding since we have w" : 3x.A{x) Ih by 
monotonicity. 

4. Suppose w.l.o.g. w : A \\-, w' > w and w' :if- A A B. Then by Lemma|5] w' :if- A. 
So w' is exploding because we have w' : A i\- by monotonicity. 
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5. Suppose w' > w and w' :lh Vx.A(x). Then by Lemma |5] w' :ih A{d). So w' is 
exploding because we have w' : A{d) it- by monotonicity. 

□ 

We can also say that forcing of ± and T behaves like expected with respect to 
exploding nodes |35ll24)] : 

Lemma 8. L w :ih T and w : ± Ih. 

2. w is exploding iffw :ih ±. 

3. w is exploding iffw:T ih. 

Proof. I. Obvious. 
2. Let w be an arbitrary world. 

w :n- ± <=> V(w' > w) (w' : ± iij => w' 

<=> V(w' > w) (w' :ihj_) <;=^ w :ihj_ 



3. Similar 



□ 



We can use the previous lemmas to show that the forcing relation for classical logic 
behaves "classically" indeed: 

Lemma 9. The following hold in the classical Kripke semantics. 

\. w A w : -lA Ifj. 

2. w : A Ih w :ih -^A. 

3. w : -iA Ih <=> w :ih A. 

4. w : -■A Ih <;=> vv : ->A iij. 

5. w :ih A •;=^ vv :ih ->-iA. 

6. w : A Ih <;=^ w : -i-iA ih. 

7. w : -lA i[j vv :ih -i-iA ih <;=^ w :ih A. 

Proof. I. Obvious by definition because w : ± ih. 

2. It follows from Lemma [5] 

3. Obvious by Lemma|7]and the previous claims. 
|4] ~|2l Obvious from the previous claims. 

□ 

Corollary 10. In any classical Kripke model, the following holds. 

w : -lA lis w :ih -i-iA <=> w :ih A 
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We now consider the following double-negation translation (■)*, which is the one of 
Godel-GentzenI T6l 151. except that atomic formulae, ± and T are not doubly negated: 



X* 


= X {X is atomic, ± or T) 


(A A BY 


= A'AB' 


(A ^ BY 


= A* ^ B* 


(Vx.A)* 


= Vx.A* 


(A V BY 


= ^(^A* A -nB*) 


{3x.AY 


= ^Vx.^A* 



Proposition 11. Every classical Kripke model C — (K, <,D, iij, il-^) gives rise to an 
intuitionistic Kripke model with exploding worlds I — (K, <, D, If-/, Ih^), which inherits 
all components ofC, except for ll-,-, which is defined for atomic formulae by non-strong 
forcing, i.e. 

w ih; X ijfw :ii- X 

The translation (•)* relates C and I, that is, for any world w and any formula A we 
have 

w hi A* ififw A. 

Proof. By induction on the complexity of A and by using (l)-(3) from Lemma |5] and 
(2) from Lemma[8] We detail only the induction case for V, which is the most involved 
one: 

w (A V B)* 

(Vw' > w) 
(Vw' > w)[ 



(Vw' > w)[ 



(Vw' > w) 
(Vw' > w) 



3. LK^;; and Soundness 

To emphasise the symmetries of classical logic, we use a sequent calculus in the 
style of Gentzen's LK as proof system. We could have directly used LK or one of its 



W Ih; -i(-iA* A -iB*) 
[w' Ih; -iA*,w' Ih,- -iB* ^> w' Ih; ±] 
(Vw" > W')[W" Ih; A* ^ W" Ih; ±], 
(Vw" > W')[W" Ih, B* ^ W" Ih; ±] 
=> W' Ih; ±] 

(Vw" > w')[w" :ih A w" lhj_], 
(Vw" > w')[w" :ih B w" ihj^] 

w' Ihj^] 

[w' : A Ih, w' : B ih=> w' ihj.] 
[w' : A V B Ii5=> w' ihj.] 
w :ih A V B 
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r\A H A, A 

r,A h A 



(Axz.) 

(A) 



r\A h A 

r h A|A r|fi h A 
FIaTsTa 

r|A h A r|fi h A 



(Vl) 



r|A V B h A 

r|A h A ^ , ^ r|B h A 



r|A A B h A 

r|A(jt;) h A 



r|A A B I- A 
X fresh 



■(Ai) 



r|3xA(x) h A 

r|A(f) H A 

r|Vx.A(jc) h A 

■Ul) 



■(3l) 



(Vl) 



r|± h A 



A,ri- A|A 

r h A,A 

Th A|A 
r,A h B|A 



(Axr) 
■(;") 



r h A ^ B|A 
ThAIA , ThBIA 



r h A VB|A 

r h A|A 



r h A V B|A 

r h B|A 



(v|) 



ThAABIA 
r h A(r)|A 



(Afi) 



(3«) 



r h 3x.A(x)|A 

r h A(x)|A X fresh 
r h VxA(x)|A 



r h T|A 



r h A|A r|A H A 
r h A 



(Cut) 



Table 1 : The sequent calculus LK^^ 



variants with impUcit structural rules, a la Kleene-Kanger. In practise, even though the 
current paper does not go into the details of the computational content of proofs, we 
rely here on LK^^ which has a simple symmetrical variant of /l-calculus as underlying 
language of proofs |8ul8.fl 

LK^^ is presented on Table[Tl It differs from LK in the following points: 

• Sequents come with an explicitly distinguished formula on the right or on the left, 
or no distinguished formula at all, resulting in three kinds of sequents: 'T i- A", 
"r|A 1- A" and 'T h A|A". Especially, the distinguished formula plays an "active" 
role in the rules. 

• Accordingly, the axiom rule splits into two variants (Ax^) and (Axr) depending 
on whether the left active formula or the right active formula is distinguished. 



Note that even if not based on /i-calculus, there are calculi of proof-terms for LK too, see e.g. I32il25ll34il . 
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There are also two new rules, (fi) and (fi), for making a formula activ^l 

There are no explicit contraction rules: contractions are derivable from a cut 
against an axiom as follows: 



- Left contraction: 



■ (Ax«) 



— ! — ! (Cut) (Lontri) 

r,A [- A 



Right contraction: 



(Axi) 



rhA|A,A r|AhA,A (r^^fr-\ 
— - — (Cut) (ContrR) 



fh A,A 



• Consequently, the notion of normal proof, or cut-freeness, is slightly different 
from the notion of cut-freeness in LK: a normal proof is, a proof whose only cuts 
are of the form of a cut between an axiom and an introduction rul^ This is the 
notion that we refer to when below, very often, we say "cut-free" or "provable 
without a cut". 

The correspondence between normal proofs of LK and normal proofs of LK^,^ is di- 
rect. If we present LK with weakening rules attached to the axiom rules a la Kleene's 
G4 or Kanger's LC, we obtain an LK proof from an LK^^ proof by erasing the bars 
serving to distinguish active formulae, and by removing the trivial inferences coming 
from the rules (/i) and {p). In the other way round, every introduction rule of LK can 
be derived in LK^^ by applying the rules (//) and (/<) on the premises and a (possibly 
dummy) contraction (i.e. a cut against an axiom) on the conclusion of the rule. Simi- 
larly for the axiom rule (for which there are two possible derivations) and the cut rule. 
For more details we refer the reader to 1^ . 

For a constant c, let Tdt), tS.c{f),Ac{t) be obtained from F, A, A by replacing each 
constant c with a term t. 

Lemma 12 (Weakening). Suppose F c F' and A c A'. 

• F h A implies F' h A'. 

• F h A I A implies F' h A | A'. 

• F I A h A implies F' | A h A'. 

Moreover, no further cuts in the derivations on the right-hand side are necessary. 
Lemma 13. Let c be a constant andy a variable which does not appear in F, A, A. 

• F h A implies Ydy) H A.c(y). 



*Note that we have to define the contexts of formulae T and A as ordered sequences to get a non ambigu- 
ous interpretation of LK^^ as a typed /1-calculus. 

^The rules (ju) and (fi) are not introduction rules, because they do not introduce a formula constructor. 
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• r h A I A implies Tdy) I- Ac(y) \ A^. (j). 

• r I A h A implies Y^y) \ A,(y) h ^ciy)■ 

Moreover, no further cuts in the derivations on the right-hand side are necessary. 

The following lemma says that a fresh constant is as good as a fresh variable and 
will play an important role in the proof of cut-free completeness below. 

Lemma 14 (Fresh constants). Let c be a constant and y a variable which does not 
appear in F, A, A. Assume furthermore that c does not appear in F, A. 

• F I- A(c) I A implies F h A(jy) | A. 

• F I A(c) h A implies F | A{y) h A. 

Moreover, no further cuts in the derivations on the right-hand side are necessary. 

Proof. It follows directly from the lemma just before. □ 

The fact that Lemma[T2]~ Lemma[T4]need not introduce any new cuts in the deriva- 
tions on the right-hand side of the implication will be important for the proof of cut-free 
completeness. 

We now show the soundness of LK^^ with respect to the Kripke semantics. First 
we need some preparations. 

Let {K, <, D, iij, ih^) be a Kripke model. Associations are functions from a finite 
set of free variables to Uu ga: D{w). The letters p, 77, ... vary over associations. Given an 
association p and a free variable x, ' denotes the function obtained from p by deleting 
X from its domain, i.e., dom(p"') = dom(p)\{x). Let p(x i-> d) denote the function p' 
such that p'iy) - p{y) ifyi^x and d otherwise. 

Let Co be a distinguished constant of the language. Given a formula A, let A[p] 
denote the sentence in the extended language with fresh constants for each element of 
D obtained from A by replacing each free variable x with p(x) if x e dom(p) and with 
Co otherwise. F[p] is the context obtained from F by replacing each A € F with A [p]. 

We write w :ih F when w forces all sentences from F and w : A ih when w refutes 
all sentences from A. 

The intuitive meaning of the following theorem is that if every formula in the as- 
sumption is forced, then not all formulae in the conclusion can be refuted. 

Theorem 15 (Soundness). Let A be a formula and F, A contexts of formulae. In any 
classical Kripke model (K, <,D, Itj, Ih^) the following holds: Let w e K and p be an 
associations with the values from D{w). 

• IfT h A, w :ih r[p] and w : A[p] ih, then w 

• IfT h A|A, w ;ih F[p] and w : A[p] Ih, then w A[p]. 

• Ifr\A h A, w F[p] and w : A[p] ih, then w : A[p] ih. 

Proof. One proves easily the three statements simultaneously by induction on the 
derivations. We demonstrate two non-trivial cases. Suppose w :if- F[p] and w : A[p] ih. 
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Case (Vl): Suppose w' > w and w' :h A[p] V B[p]. We have to show w' is 
exploding. But this follows from the fact that w' : A[p] V B[p] ih,. Note just that 
w' '-Alp] It- and w' : B[p] ih follow from the l.H. using monotonicity. 

Case (3/,): Suppose w' > w and w' (3x.A)[p]. We have to show w' is explod- 
ing. For this it suffices to show w' : (3x.A(x))[p] lij, i.e., w" : A[p(x i-> t/)]) ih 
for all w" > w' and d € D(w"). Note first that w" r[p(x i-» d)] and 
w" : A[p(.i i-» d)] Ih by monotonicity because of the freshness of x. By l.H. 
the claim follows. 

□ 



4. Completeness 

As usual when constructively proving completeness of Kripke semantics for a frag- 



menj^ of intuitionistic logic |0, 3^, we define a special purpose model, called the 
universal model, built from the deduction system itself. Once we show completeness 
for this special model, completeness for any model follows (Corollary [T9]l. 

Definition 16. The Universal classical Kripke model "Z/ is obtained by setting: 

• K to the set of pairs (F, A) of contexts ofLK^fi; 

• (F, A) < (F', A') iff both F c r and A c A'; 

• (F, A) ; X llj iff the sequent F|X h A is provable without a cut in LK^j^; 

• (F, A) :\\-^ iff the sequent F h A /i provable without a cut in LK^f,; 

• for any w, D{w) is the set of closed terms ofLKfjp. 

Note that the domain function D is a constant function, while in the abstract definition 
of model we allow for non-constant domain functions because that allows building 
more counter-models in applications. 

Monotonicity of strong refutation on atoms follows from Lemma [T2l 

Theorem 17 (Cut-Free Completeness for 1/). For any sentence A and contexts of 
sentences F and A, the following hold in 11: 

(F,A):ihA => FhAlA (1) 
(F, A) : A Ih => F|A h A (2) 

Moreover, the derivations on the right-hand side of^ and (|2]i are cut-free. 



As previously remarked, there is no constnjctive proof for full intuitionistic predicate logic. 
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Proof. We proceed by simultaneously proving the two statements by induction on the 
complexity of A. When quantifiers are concerned, A{t) has lower complexity than 
3x.A{x) and Vx.A(x). 

The derivation trees in this proof use meta-rules (*) and multi-step derivations 
(Contri, Contri) in addition to the derivation rules of the calculus from Table [1] in 
order to make the proofs easier to read. 

We also remind the reader that the notion of cut-freeness is the one of LK^,^, intro- 
duced in the previous section. 

Base case for atomic formulae. In the base case we have forcing and refutation on 
atomic sentences, which by definition reduce to strong refutation on atomic sentences, 
which by definition reduces just to statements about the deductions in LK^^. 

^ Suppose 

v(r', A') > (r. A), {Y'\x h A' => r h A') (*) 

where the RHS is cut-free. Then the following holds for F' = F and A' = X, A: 

(Axz.) 

r\XbX,A 

■ (*) 



FhX,A 

■ W 



F hXIA 
© Suppose (F, A) : X ih, i.e., 

V(F', A') > (F, A), {(F', A') -.hX ^ F' h A'} (*) 

We use (*) to prove r,X \- A without introducing a cut from which the claim 
follows by the (/i)-rule. For this, we need to show ((F, X),A) X. Assume 
(F",A") > ((F,X),A) such that there is a cut-free proof for F" | X h A". Then by 
(Contri), F" I- A", that is, (F", A") is exploding. 

Base cases for T and ±. Obvious. 

Induction case for implication. 
(HJ Suppose (F, A) A\ Ai, i.e., 

V(F',A') > (F,A),{(F',A') : Ai ^ A2 ih^ ^ F' h A') (*) 

We use (*) to prove F, Ai t- An, A without introducing a cut from which the claim 
follows by the (//) and (— rules. We need to show ((F, Ai), (A2, A)) : A\ — > 
A2 lis, i.e. ((F,Ai),(A2,A)) :ii- Ai and ((F, Ai), (A2, A)) : A2 ih. We show the first 
one. The second case is similar. 

Assume (F',A') > ((F, AO, (A, A2)) such that (F',A') : Ai iij. Using the induction 
hypothesis we get the following cut-free proof: 

r I Ai h A' 

(Contri) 



r h A' 

That is, (F', A') is exploding. 
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^ Suppose (r, A) : Ai ^ At IH, i.e., 

v(r',A') > (r,A),{(r',A') :ih Ai -4 A2 => r'hA') (*) 

We use (*) to prove r,Ai — > A2 h A without introducing a cut from which the 
claim follows by the (/i)-rule. We need to show ((r,Ai A2),A) Ai — » A2. 
Assume (r",A") > ((r,Ai A2),A) such that (r",A") Ih Ai and (r",A") : 
A2 Ih. Then, using the induction hypotheses we have the following cut-free proof: 

r'hAiiA" r"|A2HA" 



r" 1 A, ^ A, h A" 

— {Contri) 



r" H A" 



That is, (F", A") is exploding. 



Induction case for V. 
(HJ Suppose (T, A) Ai V A2, i.e., 

V(r', A') > (T, A), {(r. A') : Ai V A2 ih, ^ (H, A') ih^) (*) 

First we use (*) to show F 1- Ai, A2, Ai V A2, A without introducing a cut. For this 
we set F' = F and A' = Ai, A2, Ai V A2, A, that is, we need to show (F', A') : A,- ih 
for; = 1,2. Assume (F", A") > (F', A') such that (F", A") ;ih A,, then by induction 
hypotheses F" h A, | A". Therefore, by {Contra), (F", A") is exploding. 
Now we can prove the claim. 

F h A2,Ai,Ai V A2,A 

FhA2lAi,Ai VA2,A , 
■ (v?) 



Fh A, vA2|Ai,Ai VA2,A 

iContrR) 

F h Ai,Ai V A2, A 



Fi-AiAiVA2,A 

— (V ) 

F h Ai V A2IA1 V A2, A 

Fh Ai VA2,A~ ^^"""'"^ 

FhAiVA2|A ^' 

(|2]i The claim follows directly from the (V/,)-rule and the induction hypothesis be- 
cause (F, A) : Ai V A2 Ih implies both (F, A) : A] ih and (F, A) : A2 ih by Lemma|7] 
which does not need to introduce new cuts. 

Induction case for A. 

([TJ The claim follows directly from the (Afi)-rule and the induction hypotheses be- 
cause (F, A) :ih Ai A A2 implies both (F, A) :ih Ai and (F, A) :ih A2, by Lemma|5l 
which does not need to intruduce new cuts. 

© Suppose (F, A) : Ai A A2 Ih, i.e., 

V(F',A') > (F,A),{(F',A') :ih Ai AA2 ^ (F',A') ih^} (*) 

We use (*) to show F, Ai A A2 h A without introducing a cut from which the claim 
follows by the (/i)-rule. By Lemma|5] we need to show ((F, Ai A A2), A) :ih A,- for 
i = 1,2. Assume (F",A") > ((F,Ai A A2),A) such that (F",A") : A, H;. Using 
induction hypotheses we get the following cut-free proof: 
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r" Ai h A" 

— ■ — ■ (a;) 

IA1AA9I-A" ' 

(Conrri) 



r" h A" 

Therefore, (F", A") is exploding. 
Induction case for V. 

dill Assume (F, A) Vx.A(x). Then, by Lemma |5] (F, A) :ih A{t) for all closed 
terms. In particular, we have (F, A) :ih A(c) for some fresh constant c which does 
not occur in F, A,A. Using the induction hypothesis we get a cut-free proof of 
F I- A(c) I A. By Lemma[T4l this implies a cut-free proof of F t- A(x) | A for any 
fresh variable x, so the claim follows. 

(O Suppose (F, A) : Vx.A(x) ih, i.e., 

V(F', A') > (F, A), {(F', A') :ih Vx.A(x) ^ (F', A') Ih^) (*) 

We use (*) to show F, V.\:.A(x) t- A without introducing a cut from which the claim 
follows by the (/i)-rule, that is, we need to show ((F, Vx.A(x)), A) :ih A(f) for any 
closed term t. Assume (F", A") > ((F, Vx.A(x)), A) such that (F", A") : A(t) k. 
Using the induction hypothesis we get the following cut-free proof: 



F" I A(f) H A" 
F" I \/x.A(x) h A'' 
F" h A" 

Therefore, (F", A") is exploding. 



■ (Vl) 

■ {Contra) 



Induction case for 3. 
Suppose (F, A) :il- 3x.A{x), i.e., 

V(F', A') > (F, A), {(F', A') : 3x.A{x) k ^ (F', A') ih^) (*) 

We use (*) to show F h 3x.A{x), A without introducing a cut from which the claim 
follows using the (ju)-rule. We need to show (F, (A, 3x.A(x))) : A(t) iH for any 
closed term t. 

Assume (F", A") > (F, (A, 3x.A(x))) such that (F", A") A(t). Using the induc- 
tion hypothesis we get the following cut-free proof; 

F" h A(r) I A" 

■ (3fi) 



F" h 3x.Aix) I A" 

— (Contra) 



F" h A" 

Therefore, (F", A") is exploding. 
© Assume (F, A) : 3x.A(x) ih, then (F, A) : 3x.A(x) 1I5 by Lemma|7] That is, (F, A) : 
A(f) Ih for all closed terms. In particular, we have (F, A) : A(c) ih for some fresh 
constant c which does not occur in F, A, A. Using induction hypotheses we have 
a cut- free proof of F | A(c) I- A. By Lemma [HI this implies a cut-free proof of 
F I A{x) h A for any fresh variable, so the claim follows. 

□ 
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Corollary 18. For any sentence A and contexts of sentences F, A, the following hold 
in nA: 



1. If A erthen(r,A) :ih A. 

2. IfBeAthen(r,A):Bi\-. 

Proof 1. Assume A e T, (F, A') > (T, A) and (F, A') : A iij. Then by TheoremfTTl 
r' I A [- A', so we obtain a cut-free proof for F' t- A' using {Contri). That is, 
(F',A') is exploding. 

2. Assume B 6 A, (F', A') > (F, A) and (F', A') :ih B. Then by TheoremfTTl F' h B | 
A', so we obtain a cut-free proof for F' v- A' using {Contra). That is, (F', A') is 
exploding. 

□ 

Corollary 19 (Completeness of Classical Logic). If in every Kripke model, at every 
possible world, the sentence A is forced whenever all the sentences ofF are forced and 
all the sentences of A are refuted, then there exists a cut-free derivation in LK^^p of the 
sequent F v- A\A. 

Proof. If the hypothesis holds for any Kripke model, so does it hold for 14. Theorem 
[17]and Corollary [TSjlead to the claim, since (F, A) :ih F and (F, A) : A ih. □ 

Remark 20. The following are false, even if reasoning classically. 

• w :h Ay B implies w :\\- Aorw B. 

• w 3x.A(x) implies w A(d)for some d € D{w). 

Because of the completeness of classical logic with respect to the universal model, 
the claims correspond to Disjunction property (DP) and Explicit definability property 
(ED), respectively, which are in general not true in classical logic. 

A constructive cut-free completeness theorem can also be used for proof normali- 
sation. 

Corollary 21 (Semantic Cut-Elimination). For all contexts F, A of sentences, if there 
is a derivation o/F h A, then there is a cut-free derivation ofT h A. 

Proof. From the hypothesis F h A, the soundness theorem applied to U gives us that 
there is indeed a cut-free derivation for F h A because the world (F, A) forces all for- 
mulae of F and refutes all formulae of A as shown in Corollary[T8] □ 

5. Discussion, Related and Future Work 

5.1. Normalisation by Evaluation 

The last corollary is at the origin of our work, where we wanted to do a normalisation- 
by-evaluation (NBE) proof for computational classical logic. The general idea of the 
NBE method is to use an "evaluation" (soundness) function from the object-language 
to a constructive meta-language and then use a "reification" (completeness) function 
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from the meta-language back to the object-language. The interpretation of the object- 
language inside the meta-language, that goes via evaluation/soundness, is usually done 
using some form of Kripke models. 

So far, NBE has been used to show normalisation of various intuitionistic proof sys- 
tems isl [m 0, [H llH [30I1 as well as purely computational calcuU \12]. One advantage 
of taking this approach to that of studying a reduction relation for a proof calculus for 
classical logic, explicitly as a rewrite system, is that one circumvents both difficulties of 
rewrite systems and validating equalities arising from //-conversion. For more details 
on these difficulties the reader is referred to |33;|, for classical proof systems, and ll3 l 
for intuitionistic proof systems. Another advantage is that these kinds of proofs manip- 
ulate finite structures only and avoid working with saturated models as, for example, in 

Note also that, although as output from the NBE algorithm we get a y6-reduced t]- 
long normal form, we proved a weak NBE result, as we did not prove that the output 
can be obtained from the input by a number of rewrite steps, as it is done in j^. 



5.2. Dual Notion of Model 

Thanks to the symmetry of the LK^^ rules for left-distinguished and right-distinguished 
formulae, it is possible to define a dual notion of model in which: 

• ''strong forcing" is taken as primitive and "refutation" and non-strong "forcing" 
are defined from it by orthogonality like in Definition |2l 

• for the universal model, strong forcing is defined as cut-free provability of right- 
distinguished formulae (instead of left-distinguished ones for strong refutation), 

and prove, completely analogously to the proofs presented in this paper, that we have 
the same soundness and completeness theorems holding. 

The reader interested in the computational behaviour of the completeness theorem, 
should look at its partial Coq formalisation ll20ll . From that work it follows that the NBE 
theorem computes the normal forms of proofs in call-by-name discipline. We mention 
this work because we would like to conjecture that the presented classical Kripke model 
always gives rise to call-by-name behaviour for proof normalisation, while the dual 
notion gives rise to call-by-value behaviour. As one of the referees remarked, there is a 
variety of different strategies for doing proof normalisation, of which call-by-name and 
call-by-value are the simplest ones to describe, but also the most standard ones. For 
a general study of cut-elimination strategies that are more complex than call-by-name 
and call-by-value, the reader is referred to ifioll . 

5.3. Using Intuitionistic Kripke Models on Doubly-Negated Formulae 

Although one can define a double-negation interpretation A* of formulae and use 
intuitionistic Kripke models and an intuitionistic completeness theorem to obtain a 
normalisation result, one would have to pass through the chain of inferences 

h, A ^ H/ A* ^ hi A* ^ hf A* ^ hf A 
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where "i" stands for "intuitionistic", "c" for "classical" and "nf" for "in normal form", 
in which how to do the last inference is not obvious. We consider that to be a detour 
since we can prove, simply, the chain of inferences 

\-c A => ihc A => A 

The interest in having a direct-style semantics for classical logic is the same as the 
interest in having a proof calculus for classical logic instead of restricting oneself to 
an intuitionistic calculus and working with doubly-negated formulae; or, in the theory 
of programming languages, to having a separate constant call-cc instead of writing all 
programs in continuation-passing style. 

Avigad shows in jstl how classical cut-elimination is a special case of intuitionistic 
one, work which resembles the first chain of inferences of this subsection. However, 
his work is specialised to "negative" formulae, that is, it is not clear how to extend it to 
formulae that use V and 3. 

Finally, we remark that an interpretation through intuitionistic Kripke models and a 
double-negation interpretation would have to be done in Kripke models with exploding 
nodes, because of the meta-mathematical results from 121, 271. 



5.4. Boolean vs. Kripke Semantics for Classical Logic 

We compare Boolean and Kripke semantics in a constructive setting, based on our 
own observations (which we hope to submit for publication soon) and based on a strand 
of works in mathematical logic from the 1960s. 

Computational Behaviour The only known constructive com plet eness proof of classi- 
cal logic with respect to Boolean models is the one of Krivine 12411 . who used a double- 
negation interpretation to translate Godel's original proof. Krivine's proof was later 
reworked by Berardi and Valentini ^ to show that its main ingredient is a constructive 
version of the ultra-filter theorem for countable Boolean algebras. This theorem, how- 
ever, crucially relies on an enumeration of the members of the algebra (the formulae). 

In the work we mentioned as yet to be put into words, a formalisation in construc- 
tive type theory of the proof of Berardi and Valentini, we saw that, as a consequence of 
relying on the linear order, the reduction relation for proof-terms corresponding to im- 
plicative formulae is not y6-reduction, but an ad hoc reduction relation which depends 
on the particular way one defines the linear order (enumeration of formulae). As a 
consequence, there is no clear notion of normal form suggested by the ad hoc reduc- 
tion relation. The cut-free completeness theorem given in this paper, however, gives 
rise to a normalisation algorithm which respects the y6-reduction relation of the object- 
language, when the Kripke models are interpreted in a type theory which is based on 
j6-reduction itself. 

Expressiveness. We think of classical Kripke model validity as being more expressive, 
i.e. containing more information, than Boolean model validity. That is indicated by the 
presented completeness theorem which is both simpler than (constructive) complete- 
ness theorems for Boolean models, and manipulates finite structures directly, instead 
of relying on structures built up by an infinite saturation process. 
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Also, only after submitting the first version of the present text, we became aware 
of the work done in the 1960s on using Kripke models to do model theory of classical 
logic ll4ll . Although conducted in a classical meta-language, the work indicates that it 
is possible to use Kripke models to express ele gant ly some cumbersome constructions 
of model theory, like set theoretic forcing Igj Il4ll . Indeed, the connection between 
the two had been spotted already by Kripke 12311 and hence the term "forcing" ap- 
peared in Kripke semantics. We hope that looking at those kind of constructions inside 
Kripke models, but this time inside a constructive meta-language, might be an inter- 
esting venue to finding out the constructive content of techniques of classical model 
theory. 

In this respect, our work can also be seen as a contribution to the field of construc- 
tive model theory of classical logic. 
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